package org.demo.controller;

import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.context.ApplicationContext;
import org.springframework.security.access.prepost.PreAuthorize;
import org.springframework.stereotype.Controller;
import org.springframework.ui.Model;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.PostMapping;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.ResponseBody;

@Controller
@RequestMapping("user")
public class MyController {


	@GetMapping("/common")
    public String common() {
        return "user/common";
    }
	
	@PreAuthorize("hasAuthority('PRODUCT_LIST')")
    @GetMapping("/admin")
    public String admin() {
        return "user/admin";
    }
	
}
